The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CCanonical Ubuntu
OSCanonical10.0411.1012.0412.10Mozilla Firefox
APPMozilla< 18.010.0 – 10.0.12 (excl.)17.0 – 17.0.2 (excl.)Mozilla Seamonkey
APPMozilla< 2.15Mozilla Thunderbird
APPMozilla< 17.0.2Mozilla Thunderbird Esr
APPMozilla17.0 – 17.0.2 (excl.)10.0 – 10.0.12 (excl.)Opensuse
OSOpensuse11.412.112.2Red Hat Enterprise Linux Desktop
OSRedhat5.06.0Red Hat Enterprise Linux Eus
OSRedhat5.96.3Red Hat Enterprise Linux Server
OSRedhat5.06.0Red Hat Enterprise Linux Server Aus
OSRedhat5.9Red Hat Enterprise Linux Workstation
OSRedhat5.06.0SUSE Linux Enterprise Desktop
OSSuse1011SUSE Linux Enterprise Server
OSSuse1011SUSE Linux Enterprise Software Development Kit
OSSuse1011
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoSMemory
CWE
References
Related vulnerabilities
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2024-9680CRITICAL9.8⚠ KEVPL ✓same product
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
CVE-2022-26486CRITICAL9.6⚠ KEVPL ✓same product
Use-after-free w WebGPU IPC framework Mozilla — sandbox escape
CVE-2022-0543CRITICAL10.0⚠ KEVPL ✓same product
Redis – ucieczka z Lua sandbox umożliwiająca zdalne wykonanie kodu (RCE)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego